Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2021-26829
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.174
EPSS Ranking
94.8%
CVSS Severity
CVSS v3 Score
5.4
CVSS v2 Score
3.5
Proposed Action
OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm.
Ransomware Campaign
Unknown
References
http://forum.scadabr.com.br/t/report-falhas-de-seguranca-em-versoes-do-scadabr/3615/4
https://youtu.be/Xh6LPCiLMa8
http://forum.scadabr.com.br/t/report-falhas-de-seguranca-em-versoes-do-scadabr/3615/4
https://youtu.be/Xh6LPCiLMa8
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26829
https://www.forescout.com/blog/anatomy-of-a-hacktivist-attack-russian-aligned-group-targets-otics/
Products affected by CVE-2021-26829
Scadabr
»
Scadabr
»
Version:
Any
cpe:2.3:a:scadabr:scadabr:*
Scadabr
»
Scadabr
»
Version:
1.0ce
cpe:2.3:a:scadabr:scadabr:1.0ce
Scadabr
»
Scadabr
»
Version:
1.1.0
cpe:2.3:a:scadabr:scadabr:1.1.0
Linux
»
Linux Kernel
»
Version:
N/A
cpe:2.3:o:linux:linux_kernel:-
Microsoft
»
Windows
»
Version:
N/A
cpe:2.3:o:microsoft:windows:-
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved